Vulnerability Name:

CVE-2006-0486 (CCN-38513)

Assigned:2006-01-25
Published:2006-01-25
Updated:2017-10-11
Summary:Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2006-0486

Source: CCN
Type: SA18613
Cisco IOS AAA Command Authentication Bypass Vulnerability

Source: SECUNIA
Type: UNKNOWN
18613

Source: CCN
Type: SECTRACK ID: 1015543
Cisco IOS AAA Command Authorization Feature May Let Remote Authenticated Users Gain Elevated Privileges

Source: SECTRACK
Type: UNKNOWN
1015543

Source: CISCO
Type: Vendor Advisory
20060125 Response to AAA Command Authorization by-pass

Source: CCN
Type: cisco-sr-20060125-aaatcl
Cisco Security Response: AAA Command Authorization by-pass

Source: OSVDB
Type: UNKNOWN
22723

Source: CCN
Type: OSVDB ID: 22723
Cisco IOS tclsh Login Process Re-Use

Source: XF
Type: UNKNOWN
cisco-aaa-tcl-auth-bypass(24308)

Source: XF
Type: UNKNOWN
cisco-aaa-tclquit-auth-bypass(38513)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:4905

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:ios:12.2(25)s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:cisco:ios:12.2s:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxb:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.3t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sw:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sz:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2su:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxd:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4mr:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxf:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xa:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4xb:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.2sxe:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:12.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:4905
    V
    Cisco IOS AAA Command Authorization Bypass via TCL Shell Reuse Vulnerability
    2009-12-14
    BACK
    cisco ios 12.2(25)s
    cisco ios 12.3t
    cisco ios 12.4
    cisco ios 12.2s
    cisco ios 12.2sxb
    cisco ios 12.3t
    cisco ios 12.2sw
    cisco ios 12.2sz
    cisco ios 12.2su
    cisco ios 12.2sxd
    cisco ios 12.4mr
    cisco ios 12.4t
    cisco ios 12.2sxf
    cisco ios 12.4xa
    cisco ios 12.4xb
    cisco ios 12.2sxe
    cisco ios 12.4